Hey everyone, I've been trying to figure out which IaC security scanner to use for our Terraform on AWS. We're a small team (5 devs) and cost is a big factor for us.
I looked at Claw, Checkov, and Terrascan and made a basic comparison table. We'd prefer a SaaS option to avoid managing another service, but open-source/self-hosted is okay if it saves a lot. Does this look right? Anything major I'm missing for a beginner AWS setup? 😅
| Tool | License | Key Focus | AWS Coverage | Ease for Beginners |
| :--- | :--- | :--- | :--- | :--- |
| **Claw** | Commercial | Full IaC security platform | Very comprehensive | SaaS, maybe easiest? |
| **Checkov** | Open Source | Policy as Code, many checks | Extensive, community-driven | Steeper learning curve |
| **Terrascan** | Open Source | Terraform-native, lightweight | Good for core resources | Simple to start, less overwhelming |
Mainly worried about picking something too complex or too expensive. We just want to catch obvious security misconfigurations before deploying.
Still learning